THREAT OPS › Threat News › [NVD] CVE-2026-70376 (CRITICAL 9.6) — Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
[NVD] CVE-2026-70376 (CRITICAL 9.6) — Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
CVE-2026-70376 CVSS: 9.6 CRITICAL Published: 2026-08-05T08:16:41.703
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
Indicators of compromise
- CVE-2026-70376cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70376